HD Trust · the session-trust layer
Session-trust intelligence for the AI-fraud era.
Classifies WHO is operating, WHAT device and runtime they are using, and HOW the session connects. Catching what fingerprinting platforms architecturally cannot see. For the bank, and for the customer being targeted.
3 axes · multi-channel session signal · structured actions · SOC 2 Type 2
Live decisioning · WHO × WHAT × HOW
sess_3f81b2
Four real session patterns. Three-axis classification. One verdict each.
Privacy-conscious customer · Brave + Tor
scanning…scanning…scanning…Matrix · WHO × WHAT × HOW → verdict
—×—×—→—Verdict · action
—
3
classification axes
Multi-channel
session signals
Continuous
runtime evaluation
Real-time
decisioning latency
SOC 2 Type 2
certified
The three axes
WHO × WHAT × HOW in one decision.
Each axis compresses dozens of signals into a clear classification. Your team gets explicit, auditable outputs without exposing implementation details to attackers.
WHO
Operator identity + behavioral signal
Who is operating the session — and how are they acting?
LEGIT_OWNERCOACHEDSTOLEN_IDMULEBOT_SCRIPTAI_AGENTCatches: Account takeover · stolen-identity application · mule operators · coached-fraud (scammer instructing the customer) · AI-agent operators · operator-change mid-session · scripted-input behavior · duress patterns · remote-access-tool-driven sessions
WHAT
Device, browser, runtime integrity
What is the device — and is it authentic?
AUTHENTICPRIVACYCOMPROMISEDHEADLESSSTEALTHAI_BROWSERCatches: Stealth browsers (Multilogin / GoLogin / AdsPower) · banking trojans · remote-access trojans · headless and automated browsers · mobile emulators · runtime tampering · modified-OS devices · privacy browsers (Brave / Tor)
HOW
Connection integrity + transport
How is the session reaching you — and is it intact?
DIRECTPRIVACY_VPNPROXYTAMPEREDCatches: Commercial VPNs · residential proxy networks · mobile-proxy farms · datacenter IPs disguised as residential · Tor exit nodes · MITM redirection · session-replay attacks · SDK bypass tooling · transport-level tampering · geographic incoherence
Session-level threat coverage
Built for fraud that unfolds inside the session.
HD Trust tracks operator behavior, device integrity, and connection integrity together, preserving the context teams need when automation, coercion, malware, and proxy infrastructure overlap.
| Threat | How it presents | What incumbents see | What HD Trust sees |
|---|---|---|---|
| Voice-coercion of customer | Scammer on the phone walking your customer through a transaction. | Allow — device is legitimate, session is authenticated. | WHO catches coached-cadence + atypical destination + first-time rail + transaction-out-of-pattern. |
| Remote-access scam (RAT) | Scammer running TeamViewer / AnyDesk on the customer's device. | Allow — known device, owner is logged in. | WHO + WHAT catch RAT signal, input-lag pattern, scripted UI interaction, mouse vs typing latency split. |
| AI-agent attack | Claude/GPT/auto-browser controlling a real browser to apply for credit. | Device looks real, browser fingerprint coherent. | WHO catches inhuman timing, lack of micro-movement, decision-pause absence. |
| Stealth browser | Multilogin / GoLogin / AdsPower with fresh, coherent fingerprint. | New-device-but-coherent = allow. | WHAT evaluates stealth-browser-specific integrity signals, while HOW evaluates SDK interaction and transport patterns. |
| Push-payment scam (romance / impersonation) | Legitimate customer, legitimate device, fraudulent destination. | No fraud signal — session is clean. | WHO catches atypical-for-account behavior + stress / hesitation pattern. Combined with your payment-context (destination, beneficiary tenure), completes the detection. |
| Malware-mediated theft | Banking trojan injecting form overlays or initiating background transactions. | Form submission looks normal. | HOW catches SDK tamper, transport tamper, payload replay; WHAT catches RAT/trojan presence. |
| MITM / proxy injection | Adversary intercepting and modifying responses or replays. | TLS valid, allow. | HOW catches transport tamper, replay signature, MITM-proxy indicators. |
What HD Trust returns
No single score. A decision matrix you control.
Every decision is a structured object — not a black-box number. WHO, WHAT, and HOW classifications resolve into a cell of your matrix, and the cell is the action. Your downstream systems consume it directly; your investigators replay it; your auditors read every classification and signal that drove it.
| Field | Type | Description |
|---|---|---|
| who_classification | enum | Who is operating the session — LEGIT_OWNER · COACHED · STOLEN_ID · MULE · BOT_SCRIPT · AI_AGENT. Resolved from identity continuity, network, telephony, and behavior signal. |
| what_classification | enum | What device, browser, and runtime they are using — AUTHENTIC · PRIVACY · COMPROMISED · HEADLESS · STEALTH · AI_BROWSER. Resolved from environment integrity and resilience signal. |
| how_classification | enum | How the session reaches you — DIRECT · PRIVACY_VPN · PROXY · TAMPERED. Resolved from connection integrity, transport, and network signal. |
| action | enum | APPROVE · PROTECT · STEP_UP · REVIEW · BLOCK — read from the WHO × WHAT × HOW cell of your decisioning matrix. No single score; the matrix cell is the decision. |
| matrix_policy_version | string | Which version of your decisioning matrix produced this verdict. Versioned and replayable. |
| dimension_evidence | object<dimension, signal> | Underlying evidence per axis — WHO, WHAT, HOW — plus network, telephony, behavior, and resilience signals. The inputs that drove the classifications. |
| reason_codes | array<code> | Top-K explainable signal drivers, mapped to consumer-facing reason language where applicable. |
| linked_sessions | array<session_id> | Other recent sessions sharing identifiers or behavioral signature (consortium-aware). |
| trajectory | enum | Trust trajectory across the session: STABLE · IMPROVING · DEGRADING · COMPROMISED. |
How it plugs in
Eight ways into your stack.
Web, mobile, server, streaming, webhook, dashboard, data lake, SIEM. HD Trust meets your architecture — not the other way around.
Web SDK
JavaScript drop-in. Three lines of code. Collects behavioral, device, and network signal. SPA-aware.
Mobile SDKs
Native iOS (SPM / CocoaPods), Android (Gradle / Maven), React Native, Flutter, Capacitor. Background-safe, battery-conscious.
REST API
Server-side scoring. Authenticated calls return a full verdict object. Idempotent. Low-latency.
Streaming / gRPC
High-throughput pipelines (Kafka, Pub/Sub, gRPC). For real-time decisioning at issuer / acquirer / network volumes.
Webhooks
Live APPROVE / PROTECT / STEP_UP / BLOCK actions delivered to your downstream systems as the signal evolves through the session.
Dashboard
Investigate cases, tune thresholds, manage allow / negative lists, review verdict explainability, run replays.
Data-lake export
Stream every scored session into your data lake (S3, GCS, Snowflake, BigQuery, Databricks) for downstream analytics and audit retention.
SIEM integration
Splunk, Sentinel, Chronicle, Elastic. Trust events surface alongside the rest of your security telemetry.
Use cases
Wherever money or value — or trust — moves.
HD Trust scores the session at every point an attacker can move money, value, or identity — from the login screen to the final payout. And at every point a customer is being targeted by someone else who's trying to do the same.
Identity moments
Login & authentication
Credential stuffing, ATO, bot logins, session hijack, SIM-swap-driven access. Caught before they touch the application.
Account opening
Synthetic identity, application fraud, mule onboarding, KYC fraud — flagged at signup, not at the chargeback.
Account changes
Password, email, phone, device, beneficiary changes — the silent precursor to almost every ATO event.
Customer authentication
Voice-channel authentication, deepfake defense, high-stakes call verification with cross-channel coherence.
Money & value movement
Checkout & payments
Card-not-present, BNPL, wallet pay, P2P transfer — every transaction scored before authorization.
Withdrawals & payouts
ACH, wire, crypto, gift-card cash-out, lending disbursement — the moment funds leave the platform.
Push-payment review
Zelle, Real-Time Payments, RTP — scoring the legitimate-session-but-targeted-customer case.
Refunds & returns
Refund abuse, friendly fraud, returnless-refund exploit, return-of-empty-box schemes.
Promotion, marketplace & loyalty
Promo & loyalty redemption
Sign-up bonus farming, coupon stacking, loyalty-point cash-out, referral abuse.
Marketplace & e-commerce
Listing fraud, seller takeover, fake-review rings, on-platform value exchange.
KYC & document submission
Document forgery, deepfake selfies, recycled-identity packets — caught before the ops team reviews them.
Insurance applications
Bot-driven quoting, ghost-broker rings, agent-fraud signal at policy bind.
Deployment
Start with a focused SDK and server-side integration.
A focused integration.We don't replace your decisioning — we feed it a better signal that your existing rules consume.
Browser
Web or mobile collection
<script
src="https://hudsondata.com/static/hd-detect.js"
data-api-key="..."
data-auto="true">
</script>SDK observes the session in real time. No verdict ever reaches the browser.
Your backend
Server-side decision call
POST /v1/session/decide
{ session_id,
binding_token,
application_data }
Response:
{ action: APPROVE | PROTECT | STEP_UP
| REVIEW | BLOCK,
who, what, how,
reasons: [...] }One call, one structured decision. Plug it into your existing rules engine.
Hudson-managed SaaS today. SOC 2 Type 2, US / EU / India data residency, per-tenant isolation.
Frequently asked
Questions buyers ask first.
The ones that come up in every first conversation. Honest answers, no marketing fog.
How is HD Trust different from device-fingerprinting platforms?
Does HD Trust replace my existing fraud platform?
How long does integration take?
Does HD Trust output a fraud score?
What is PROTECT, and why is it a distinct action?
Can we customize the decisioning matrix?
What threats does HD Trust actually catch?
Does HD Trust collect PII?
Where does the data live?
How does HD Trust support GDPR and CCPA obligations?
How does HD Trust affect page-load performance?
Does the verdict ever reach the browser?
What happens if HD Trust is down?
Do you give us a dashboard and investigation tools?
How is HD Trust priced?
Does HD Trust work across B2C, B2B, and marketplaces?
How does HD Trust keep up with new threats?
Question not here? Send it our way →
What HD Trust isn't
Structured session intelligence, not another black-box score.
HD Trust is a three-axis decisioning matrix (WHO × WHAT × HOW) fed by explainable signal channels and composed at decision latency. It is designed for teams that need structured actions, replayable evidence, and policy control at the moment of risk.
Start with the audit
See where AI-era fraud is hitting you.
The AI-Fraud Audit produces a written assessment of your session-trust posture against the AI-era threats fingerprinting platforms miss. Vendor-neutral. Senior-team-delivered. Three weeks end-to-end.

